
Ein benutzerfreundliches Python-Tool zur Durchführung von Subdomain-Enumeration, Endpunkt-Erkennung und mehr.
Der Zweck dieses Tools ist es, Bug Hunter und Pentester bei der Reconnaissance zu unterstützen…
Kann auf jedem System mit Python3 verwendet werden
Sie können SR-71 einfach mit pip installieren:
pip3 install SR-71
Um es zu nutzen, geben Sie einfach "SR-71" in Ihrem Terminal ein
Wenn Sie es aus dem Quellcode installieren möchten:
git clone https://gitlab.com/Edu0x01/SR-71.git
cd SR-71
pip3 install -r requirements.txt
SR-71 - All in One Recon Tool
options:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN domain to search its subdomains
-o OUTPUT, --output OUTPUT file to store the scan output
-t TOKEN, --token TOKEN api token of hunter.io to discover mail accounts and employees
-p, --portscan perform a fast and stealthy scan of the most common ports
-a, --axfr try a domain zone transfer attack
-m, --mail try to enumerate mail servers
-e, --extra look for extra dns information
-n, --nameservers try to enumerate the name servers
-i, --ip it reports the ip or ips of the domain
-6, --ipv6 enumerate the ipv6 of the domain
-w, --waf discover the WAF of the domain main page
-b, --backups discover common backups files in the web page
-s, --subtakeover check if any of the subdomains are vulnerable to Subdomain Takeover
-r, --repos try to discover valid repositories and s3 servers of the domain (still improving it)
-c, --check check active subdomains and store them into a file
--secrets crawl the web page to find secrets and api keys (e.g. Google Maps API Key)
--enum stealthily enumerate and identify common technologies
--whois perform a whois query to the domain
--wayback find useful information about the domain and his different endpoints using The Wayback Machine and other services
--all perform all the enumeration at once (best choice)
--quiet dont print the banner
--version display the script version
Eine Liste von Beispielen für die Verwendung des Tools auf verschiedene Weise
python3 SR-71.py -d example.com
python3 SR-71.py -d example.com --output domains.txt
python3 SR-71.py -d example.com --quiet
python3 SR-71.py -d example.com -n -p -w -b --whois --enum # Você pode usar outros parâmetros, consulte o painel de ajuda
python3 SR-71.py -d domain.com --all
☑ Aufzählung von Subdomains mit passiven Techniken (wie "subfinder")
☑ Viele zusätzliche Abfragen zur DNS-Aufzählung
☑ Domain-Zonenübertragungsangriff
☑ WAF-Typ-Erkennung
☑ Allgemeine Aufzählung (CMSs, Reverse Proxies, jQuery…)
☑ Zieldomäne "Whois"
☑ Subdomain-Übernahme-Prüfer
☑ Prüfung auf häufig offene Ports
☑ Überprüft aktive Subdomains (wie "httprobe" )
☑ Wayback-Machine-Unterstützung zur Endpunkt-Aufzählung (wie "waybackurls" )
☑ E-Mail-Harvesting
Das Tool nutzt verschiedene Dienste, um Subdomains auf unterschiedliche Weise zu erhalten
Der WAF-Detektor wurde aus dem Konzept von CRLFSuite modifiziert und angepasst <3
Alle DNS-Abfragen verwenden zu 100% dns-python, es sind kein digging oder zusätzliche Tools erforderlich
E-Mail-Sammelfunktionen werden mit der Hunter.io-API mit persönlichem Token (kostenlose Registrierung) durchgeführt
##Extra
Wenn Sie dieses Projekt nützlich finden, würde ich mich über eine Unterstützung in Form eines Sterns für dieses Repository oder einen Kaffee sehr freuen.
Urheberrecht © 2023, Edu0x01